PT-2026-56604 · Canonical · Openjdk

·

CVE-2026-10037

·

Published

2026-07-08

·

Updated

2026-07-10

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenJDK packages provided in Ubuntu (affected versions not specified)
Description A sandbox escape issue exists where .jar MIME handlers execute files marked as executable if the mailcap package is installed. A malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10037
USN-8518-1

Affected Products

Openjdk